AMENDMENT AND RESPONSE UNDER 37 CFR § 1.111 Page 2 

Serial Number: 09/500,601 Dkt: 2062.001US1 

Filing Date: Feb 8, 2000 

Title: SYSTEM AND METHOD FOR SECURE NETWORK PURCHASING 

Assignee: iPass Inc. 



IN THE CLAIMS 

Please amend the claims as follows: 

1-15. (Canceled) 

16. (Currently Amended) A computer-implemented method for facilitating an electronic 
commerce transaction by remotely v erifying a user and a user computer involved in the 
electronic commerce transaction, the method comprising : 

receiving, in a verification computer, a request for verification from a user computer; 
in response to the request for verification, sending at least one request to the user 
computer; 

receiving at least one response from the user computer, the at least one response 

including a first computer fingerprint file and a first identification for the user 
generated using the first computer fingerprint file, said first computer fingerprint 
file including at least one identifying characteristic [[of]] associated with at least 
one hardware component of the user computer; 

comparing the first computer fingerprint file, which includes at least one identifying 
characteristic associated with at least one hardware component of the user 
computer, against a second computer fingerprint file, to verify the user computer, 
the second computer fingerprint file accessible by the verification computer, said 
second computer fingerprint file including at least one identifying characteristic 
[[of]] associated with at least one hardware component of the a -user computer; 

comparing the first identification for the user against a second identification for the user 
to verify the user, the second identification for the user accessible by the 
verification computer; and 

sending at least one verification response to the user computer, based upon the comparing 
of the first computer fingerprint file against the second computer fingerprint file 
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and upon the comparing of the first identification for the user against the second 
identification for the user. 

17. (Previously Presented) The method according to claim 16 wherein the verification 
computer is a clearinghouse computer. 

18. (Previously Presented) The method according to claim 16 wherein the verification 
computer is a vendor computer. 

19. (Previously Presented) A method according to claim 16, wherein said sending of at least 
one request to a user computer includes: 

sending a first request to the user computer for the first computer fingerprint file; and 
sending a second response to the user computer for the first identification for the user. 

20. (Previously Presented) A method according to claim 16, wherein said receiving of at 
least one response from the user computer includes: 

receiving a first response from the user computer including the computer fingerprint file; 
and 

receiving a second response from the user computer including the first identification for 
the user. 

21 . (Previously Presented) A method according to claim 20, wherein the second response 
from the user computer is received prior to first response from the user computer. 

22. (Previously Presented) A method according to claim 16, wherein said comparing of the 
first computer fingerprint file against a second computer fingerprint file, and comparing 
the first identification for the user against a second identification for the user are not 
performed simultaneously. 



23. 



(Currently Amended) A method according to claim 16_[[18]], wherein said sending of at 
least one response to the vendor computer, based upon the comparing of the first 
computer fingerprint file against the second computer fingerprint file and upon the 
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comparing of the first identification for the user against the second identification for the 
user includes sending a confirmation only when both the first computer fingerprint file 
and the first identification of the user match the second computer fingerprint file and the 
second identification for the user respectively. 

24. (Previously Presented) A method according to claim 16[[19]], wherein said receiving of 
at least one response from the user computer includes: 

receiving a first response from the user computer including the first computer fingerprint 
file; and 

receiving a second response from the user computer including the first identification for 
the user. 

25. (Previously Presented) A method according to 24, wherein the second response from the 
user computer is received prior to the first response from the user computer. 

26. (Previously Presented) A method according to claim 16, wherein the first identification 
for the user includes a password. 

27. (Previously Presented) A method according to claim 16, wherein the first computer 
fingerprint file includes information based upon an identification number of a CPU of the 
user computer. 

28. (Previously Presented) A method according to claim 16, wherein the first computer 
fingerprint file includes information based upon a MAC address associated with the user 
computer. 

29. (Previously Presented) A method according to claim 1 6, wherein prior to the receiving of 
the first request from the verification computer, storing the second computer fingerprint 
file in a first data base accessible by verification computer, and storing the second 
identifications for the user in a second database accessible by the verification computer. 
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30. (Previously Presented) A method according to claim 16[[ 18]], wherein prior to the 
receiving of the first request from the vendor computer, storing the second computer 
fingerprint file in a first data base accessible by a clearinghouse computer, and storing the 
second identifications for the user in a second database accessible by a clearinghouse 
computer. 

3 1 . (Currently Amended) A method according to claim 30_[[28]], wherein the first database 
and second database are the same. 

32. (Currently Amended) A method according to claim 16[[18]], wherein the receiving of a 
request from a vendor computer includes receiving an internet address of the user 
computer. 

33. (Previously Presented) A method according to claim 32, wherein prior to the sending of 
the at least one request to the user computer, identifying the user computer based upon 
the internet address received from the vendor computer. 

34. (Currently Amended) A clearinghouse computer for facilitating an electronic commerce 
transaction, the clearinghouse computer comprising : 

a storage unit configured to store information received from a user computer, the 
information including a second computer fingerprint file and a second 
identification for a user, said second computer fingerprint file including at least 
one identifying characteristic of [[a]] at least one hardware component of the user 
computer; 

a memory unit configured t o receive information indicative of a first computer fingerprint 
file and a first identification for the user, said first computer fingerprint file 
including at least one identifying characteristic of at least one hardware 
component of the user computer and the first identification for the user generated 
using the first computer fingerprint file; and 
a processor configured to communicate with the storage unit and the memory unit, to 
compare information indicative of the second computer fingerprint file and the 
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second identification for the user with information indicative of the first computer 
fingerprint file , identifying the user computer and the first identification for the 
user, and to cause a message to be generated based upon the comparing. 

35. (Previously Presented) A clearinghouse computer according to claim 34, wherein the 
storage unit includes: 

a first storage location to store the second computer fingerprint file, and 
a second storage location to store the second identification for the user. 

36. (Previously Presented) A clearinghouse computer according to claim 34, wherein the 
memory unit includes: 

a first memory location to store at least temporarily, the first computer fingerprint file, 

and a second memory location to store at least temporarily, the first identification 
for the user. 

37. (Previously Presented) A clearinghouse computer according to claim 34, further 
including: 

an output to receive the message to be generated based upon the comparison, and the 
output further to communicate with a vendor computer. 

38. (Previously Presented) A clearinghouse computer according to claim 34, wherein the 
second identification for the user includes a password. 

39. 39. (Previously Presented) A clearinghouse computer according to claim 34, wherein the 
second computer fingerprint file includes information based upon an identification 
number of a CPU of the user computer. 

40. -49. (Canceled) 



